Healthy and suitable to depend on. It has a long release history, a current stable release with documented fixes, active repository work from four contributors, and solid tests and documentation; the main caveats are no security policy or automated security scanning and workflows without explicit top-level permissions.
88%
Total Score
75
100
94
80
The package is backed by a personal repository rather than an organization, so the single registry maintainer and contributor concentration warrant some attention. However, current activity from four repository contributors and a fresh release provide meaningful compensation.
The leading contributor made 70% of recent commits, which is somewhat concentrated, but three other contributors each remained active during the same period. The concentration is therefore a manageable caution rather than a severe abandonment risk.
Composer build tooling is present, but no security-scanning tool was detected. For a package whose purpose is sanitizing untrusted SVG input, this is a meaningful transparency and assurance gap despite the active test suite.
The repository has no security policy. That leaves vulnerability-reporting and response expectations undocumented, which matters for a security-focused sanitizer.
Both workflows lack top-level token-permission declarations, although neither requests top-level write permissions. Explicit least-privilege declarations would improve CI transparency and reduce configuration ambiguity.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-597685 enshrined/svg-sanitize is vulnerable to Denial of Service in versions 0.22.0 - 0.22.0. | 0.22.0 - 0.22.0 | Medium |
AIKIDO-2026-531171 enshrined/svg-sanitize is vulnerable to Denial of Service in versions 0.13.0 - 0.22.0. | 0.13.0 - 0.22.0 | Medium |
AIKIDO-2026-29108 enshrined/svg-sanitize is vulnerable to Information Exposure in versions 0.0.1 - 0.22.0. | 0.0.1 - 0.22.0 | Low |
AIKIDO-2026-387398 enshrined/svg-sanitize is vulnerable to Cross-Site Scripting (XSS) in versions 0.13.0 - 0.22.0. | 0.13.0 - 0.22.0 | High |
CVE-2025-55166 enshrined/svg-sanitize is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 0.22.0. | 0.0.0 - 0.22.0 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.